Security: CVE-2026-93697 Stored XSS in WHM’s Account Modification Interfaces – September 29, 2026
CVE-2026-93697 is a stored XSS vulnerability in the WHM Mass Modify Accounts interface that allows arbitrary code execution, disclosed by cPanel on September 29, 2026. An unprivileged account holder can run script inside a WHM administrator's session, so update cPanel/WHM to a patched release promptly.
SharedLicense लाइसेंस के तहत इसका अर्थ
Successful exploitation lets an unprivileged account holder execute script in the context of a WHM administrator's session and perform administrative actions as that user.
Situation
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
Affected Product Versions
| Product | Affected Versions | Patched Versions |
|---|---|---|
| cPanel/WHM | All supported versions |
|
Impact
Successful exploitation allows an unprivileged account holder to execute script in the context of a WHM administrator’s session, which can be used to perform administrative actions as that user.
Call to action
Update to the latest patched version: How do I update cPanel/WHM?
अक्सर पूछे जाने वाले प्रश्न
What is CVE-2026-93697?
Which cPanel/WHM versions are affected and which are patched?
How do I fix CVE-2026-93697?
Is CVE-2026-93697 being exploited in the wild?
अपने सिस्टम में भेद्यताओं की जाँच करें
अपना उत्पाद और ऑपरेटिंग सिस्टम चुनें ताकि आपके लिए लागू सटीक फिक्स कमांड देख सकें।
अपना सिस्टम जाँचें